# Filebeat extract\_array for panw module for config and system logs

**URL:** <https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512>\
**Category:** Beats\
**Tags:** filebeat\
**Created:** [June 24, 2020, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512 "2020-06-24T14:59:44Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [June 24, 2020, 2:59pm UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512/1 "2020-06-24T14:59:44Z")

</div>

Are there any examples of extract\_array for palo alto firewalls for config and system logs?

ref: [https://github.com/elastic/beats/blob/e99074029172a9c6d01f953005c3cdc2b58d6cb2/x-pack/filebeat/module/panw/panos/config/input.yml](https://github.com/elastic/beats/blob/e99074029172a9c6d01f953005c3cdc2b58d6cb2/x-pack/filebeat/module/panw/panos/config/input.yml)

---

<div class="post-metadata">

**Author:** ![Kaiyan\_Sheng](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/kaiyan_sheng/32/38247_2.png) [@Kaiyan\_Sheng](https://discuss.elastic.co/u/Kaiyan_Sheng)\
**Post date:** [June 25, 2020, 12:58am UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512/2 "2020-06-25T00:58:42Z")

</div>

Sorry I don't think I understand your question 🤔 `extract_array` is a filebeat processor: [https://www.elastic.co/guide/en/beats/filebeat/7.8/extract-array.html](https://www.elastic.co/guide/en/beats/filebeat/7.8/extract-array.html)

If you want to use the panw module, you can use `./filebeat modules enable panw` and then you should see `panw.yml` in modules.d folder, which looks like [https://github.com/elastic/beats/blob/master/x-pack/filebeat/modules.d/panw.yml.disabled](https://github.com/elastic/beats/blob/master/x-pack/filebeat/modules.d/panw.yml.disabled)

---

<div class="post-metadata">

**Author:** ![gadelkareem](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/gadelkareem/32/71031_2.png) [@gadelkareem](https://discuss.elastic.co/u/gadelkareem)\
**Post date:** [June 25, 2020, 9:40am UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512/3 "2020-06-25T09:40:30Z")

</div>

Currently the panw module only parses Traffic and threat logs. I need to also parse config and system logs which are sent to Elastic Search.

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [July 23, 2020, 11:40am UTC](https://discuss.elastic.co/t/filebeat-extract-array-for-panw-module-for-config-and-system-logs/238512/4 "2020-07-23T11:40:31Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
